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(origii^) A method for broadcast encryption, comprising: 



assigning each user in a group of users respective private information 1^; 
selecting at least one session encryption key K; 

partitioning users not in a revoked set R into disjoint subsets Sii,...S|b, having associated 
subset keys L;,,...L^; and 

encryptiQg the session key K with the subset keys L^,^...,!^ to render m encrypted versions 
of the session key K. 

2. (original) The method of Claim ] , further comprising partitioning the users into groups 
S| wherein "w" is an integer, and the groups establish subtrees in a tree. 

3. (original) The method of Claim 2, wherein the tree is a complete binary tree. 

4. (original) The method of Claim 1, further conqprising using private information 1^ to decrypt 
the session key, 

5. (original) The method of Claim 4, wherein the act of decrypting includes using information 
ij such that a user belongs to a subset S^, and retrieving a subset key L,j using the private information of the 
user. 
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6. (original) The method of Claim 2, wherein each subset Sjl,...Si.u includes all leaves in a 
subtree rooted at some node V;, at least each node in the subtree beir^ associated with a respective subset key. 

7. (original) The method of Claim 6, wherein content is provided to users in at least one message 
defining a header, and the header includes at mo^ r'*'log(N/r) subset keys and encryptions, wherein r is the 
number of users in the revoked set R and N is the total iwmber of users. 

8. (origbal) The me^od of Claim 6, wherein each user must store log N keys, wherein N is 
the total number of users. 

9. (original) The method of Claim 6, wherein content is provided to users in at least one 
message, and wherein each user processes the message using at most log log N operations plus a single 
decryption operation, wherein N is ite total number of users. 

10. (original) The method of Claim 6, wherein the revoked set R defines a spanning tree, and 
subtrees having roots attached to nodes of the spanning tree define the subsets. 

11. (origimJ) The method of Claim 2, wherein the tree includes a root and plural nodes, each 
node having at least one associated label, and wterein each subset mcludes all leaves in a subtree rooted at 
some node Vj that are not in the subtree rooted at some other node Vj that descends from Vj« 
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12. (origiiial) The method of Claim 11, wherein content is provided to users in at least one 
message defining a header, and the header includes at most 2r-l subset keys and encryptions, wherein r is 
the number of users in the revoked set R. 

13. (original) The method of Claim 11, wherein each user must store .5lQg^ N + .51og N <f 1 
keys, wherein N is the total number of users. 

14. (original) The method of Qaim 11 « wherein content is provided to users in at least one 
message, and wherein each user processes the message using at most log N operations plus a single 
decryption operation^ wherein N is the total number of users, 

15- (original) The method of Claim 11, wherein the revoked set R defines a spanning tree, and 
wherein the method includes: 

initializing a cover tree T as the spanning tree; 

iteratively removing nodes from the cover tree T and adding nodes to a cover until the cover 
tree T has at most one node. 

16. (original) The method of Claim 1 1 , wherein each node has at least one label possibly induced 
by at least one of its ancestors, and wherein each user is assigned labels from all nodes hangiitg from a direct 
path between the user and the root but not from nodes in the direct path. 
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17. (original) The method of Claim 16, wherein labels are assigned to subsets using a 
pseudorandom sequence generator, and the act of decrypting includes evaluating the pseudorandom sequence 
generator. 

18. (original) The method of Claim 1 , wherein content is provided to users in at least one message 
having a header including a cryptographic function E, * and the method includes prefix-truncating the 
cryptographic function E^. 

19. (original) The method of Claim 2» wherein the tree includes a root and plural nodes, each 
node having an associated key, and wherein each user is assigned keys from all nodes in a direct path between 
a leaf representing the user and the root. 

20. (original) The method of Claim 1 , where'm content is provided to users in at least one message 
defining plural portions* and each portion is encrypted with a respective session key. 

21. (original) A computer program device, comprising: 

a computer program storage device including a program of instructions usable by a computer, 
comprising; 



logic means for accessing a tree to identify plural subset keys; 



logic means for encrypting a nwssage with a session key; 
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logic means for encrypting the session key at least once with each of the subset keys to render 
encrypted versions of the session key; and 

logic means for sending the encrypted versions of the session key in a header of the message 
to plural stateless receivers* 

22. (original) The computer program device of Claim 21, further comprising: 

logic means for partitioning receivers not in a revoked set R into disjoint subsets Sj|,...SjM 
having associated subset keys L^, . » . Xkn* 

2i. (original) The computer program device of Claim 22, further coniprising logic means for 
partitioning the users into groups S|,.*.,Sw, wherein "w** is an integer, and the groups establish subtrees in 
a tree. 

24. (original) The computer program device of Claim 21, further oonq>rising logic means for 
using private information to decrypt the session key. 

25. (original) The computer program device of Claim 24, wherein the means for decrypting 
includes Ic^ic means for using information i^ such that a receiver belongs to a subset S^, and retrieving a key 
Lg from the private information of the receiver. 
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26. (original) The computer prograin device of Claim 23, wherein each subset S;, , . . .S-^ includes 
all leaves in a subtree rooted at some node v^, at least each node in the subtree being associated with a 
respective subset key. 

27. (original) The computer program device of Claim 26, wherein logic means provide content 
to receivers in at least one message defining a header, and the header includes at most r*1og(N/r) subset keys 
and encryptions > wherein r is the number of receivers in the revoked set R and N is the total number of 
receivers, 

28* (original) The computer program device of Qaim 26, wherein each receiver must store log 
M keys, wherein N is the total number of receivers. 

29. (original) The computer program device of Claim 26 ^ wherein logic means provide content 
to receivers in at least one message, and wherein each receiver processes the message using at most log log 
N operations plus a sitigle decryption operation, wherein N is the total number of receivers* 

30. (original) The computer program device of Claim 26, wherein the revoked set R defines a 
spanning tree, and subtrees having roots attached to nodes of the spaniung tree define the subsets. 

3J» (original) The computer program device of Claim 23» wherein the tree includes a root and 
plural nodes, each node having at least one associated label, and wherein each subset includes all leaves in 
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a subtree rooted at some node that are not in the subtree rooted at some other node Vj that descends from 



32. (origmal) The computer program device of Claim 31, wherein logic means provide content 
to receivers in at least one message defining a header, and the header inchides at most 2r-l subset keys and 
encryptions, wherein r is tlie number of receivers in the revoked set R. 

33. (original) The computer program device of Claim 31 , wherein each receiver must store .51og^ 
N + .51og N +1 keys, wherein N is the total number of receivers* 

34. (original) The computer program device of Claim 31, wherein logic means provide content 
to receivers in at least one message, and wherein each receiver processes the message using at most log N 
operations plus a single decryption operation, wherein N is the total number of receivers. 



35. (original) The computer program device of Claim 31, wherein the revoked set R defines a 
spanning tree, and wherein (original) The computer program device includes: 

logic means for initializing a cover tree T as the spanning tree; and 
logic means for iteratively removing nodes from the cover tree T and adding nodes to a cover 
until Che cover tree T has at most one node* 
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36. (original) The computer program device of Claim 35, wherein logic means assign labels to 
receivers using a pseudorandom sequence generator, and the labels induce subset kpys. 

37. (original) The computer program device of Claim 36, wherein the means for decrypting 
includes evaliiatii^ the pseudorandom sequence generator. 

38. (original) The computer program device of Claim 21, wherein logic means provide content 
to receivers in at least one message hacving a header including a cryptographic function E^^, and (original) The 
computer program device includes logic means for prefix-truncating the cryptographic function El. 

39. (original) The computer program device of Claim 23, wherein d:ie tree includes a root and 
plural nodes, each node having an associated key, and wherein logic means assign each receiver keys from 
all nodes in a direct path between a leaf representing the receiver and the root. 

40. (original) The computer program device of Claim 21, wherein logic means provide content 
to receivers in at least one message defining plural portions, and each portion is encrypted with a respective 
^ssion key. 

41 . (previously presented) A computer programmed with instruaious to cause the computer to 
execute method acts includuig: 

encrypting broadcast content; and 

I0S3.I2I.AM1 
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sending the broadcast content to plural stateless receivers and to at least one revoked receiver 
such that each stateless receiver can decrypt the content and the revoked receiver cannot decrypt die 
content. 

42. (original) The computer of Claim 41, wherein the nnethod acts further comprise: 
assigning each receiver in a group of receivers respective private information !„; 
selecting at least one session encryption key K; 

partitioning all receivers not in a revoked set R into disjoint subsets S|j,...Sio, having 
associated subset keys Lji Lia^l and 

encrypting the session key K with the subset keys Li„...,Li„i to render m encrypted versions 
of the session key K. 

43. (original) The computer of Claim 41 , wherein the method acts undertaken by die computer 
further comprise partitioning die users into groups S|„,„S„, wherein "w" is an integer, and the groups 
establish subtrees in a tree. 

44. (original) The conqmter of Claim 43, wherein the tree is a complete binaiy tree. 
44. (canceled). 
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45. (original) The computer of Claim 44, wherein the act of decrypting undertaken by the 
computer includes using information ij such that a receiver belongs to a subset S^^ and retrieving a key L-^ 
using the private information of the receiver. 

46* (original) The computer of Claim 43, wherein each subset Su^.-.S^q, inchides all leaves in a 
subtree rooted at some node Vi, at least each node in the subtree being associated with a respective subset key, 

47« (original) The computer of Claim 46, wherein content is provided to receivers in at least one 
message defmirig a header, and the header includes at most r'*'log(Nyr) subset keys and encryptions, wherein 
r is the number of receivers in the revoked set R and N is the total number of receivers. 

48. (original) The computer of Claim 46, wherein each receiver must store log N keys, wherein 
N is the total number of receivers, 

49. (origii^) The conq)uter of Claim 46, wherein content is provided to receivers in at least one 
message, and wherein each receiver processes the message using at most log log N operations plus a single 
decryption operation, wherein N is the total nuiiiber of receivers. 

50. (original) The conq^uter of Claim 46, wherehi the revoked set R defines a spanning tree, and 
subtrees havir^ roots attached to nodes of the spanning tree define the subsets. 
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51 . (original) The coinputer of Claim 43, wherein the tree includes a root and plural nodes, each 
node having at least one associated label, and wherem each subset includes all leaves in a subtree rooted at 
some node Vj that are not in the subtree rooted at some other node Vj that descends from Vf. 

52. (original) The con^uter of Claim 51, wherein content is provided to receivers in at least one 
message defining a header, and the header includes at most 2r-l subset keys and encryptions* wherein r is 
the number of receivers in the revoked set R, 

53* (original) The computer of Qaim 51, wherein each receiver must store .51og^ N + .5log N 
1 keys, wherein N is the total number of receivers. 

54. (original) The computer of Claim 51, wherein content is provided to receivers in at least one 
message^ and wherein each receiver processes the message using at most log N operations plus a single 
decryption operation, wherein N is the total number of receivers. 

55. (original) The con^uter of Claim 5 1 , wherein the revoked set R defines a spanning tree, and 
wherein the method acts undertaken by the computer further include: 

initiaiizing a cover tree T as the spanning tree; 

iteratively removing nodes from the cover tree T and adding nodes to a cover until the cover 
tree T has at most one node. 
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56. (original) The computer of Claim 55, wherein the conqniter assigns node labels to receivers 
from the tree using a pseudorandom sequence generator. 

57. (original) The computer of Claim 56, wherein the act of decrypting undertaken by the 
computer includes evaluating the pseudorandom sequence generator. 

58. (original) The computer of Claim 41, wherein content is provided to receivers in at least one 
message having a header including a cryptographic function and the method acts undertaken by the 
computer include prefix-truncating the cryptographic function E,., 

59. (original) The computer of Claim 41, wherein content is provided to receivers in at least one 
message defining plural portions, and each portion is enciypted by the computer with a respective session 



60. (original) The method of Claim 11 , wherein each node has plural labels with each ancestor 
of the node inducing a respective label, and wherein each user is assigned labels from all nodes hanging from 
a direct path between the user and the root but not from nodes in the direct path. 

61. (original) A method for broadcast encryption, comprising: 

assigning each user in a group of users respective private information l^; 
selecting at least one session encryption K; 



key. 
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partitioning all users into groups S^,,..,S^j wherein "w" is an integer, and the groups establish 
subtrees in a tree; 

partitioning users not in a revoked set R into disjoint subsets S„,...S^| having associated 
subset keys Lii,««.Li„; and 

encrypting the session key K with the subset keys Ln,,,,,L^ to render m encrypted versions 
of the session key K, wherein the tree includes a root and plural nodes, each node having at least one 
associated label, and wherein each subset includes all leaves in a subtree rooted at some node Vj that 
are not in the subtree rooted at some other node Vj that descends £rom v^. 
62-64 (canceled)* 

65. (previously presented) A receiver of content, comprising: 
means for storing respective private information I„; 

means for receiving at least one session encryption key K encrypted with plural subset keys^ 
the session key encrypting content; and 

means for obtaining at least one subset key using the private information such that the session 
key K can be decrypted to play the content, wherein the receiver receives content in at least one 
message defining a header, and the header includes at most r*log(N/r) subset keys and enciyptions, 
wherein t is the number of receivers in a revoked set R and N is the total number of receivers. 

66. (original) The receiver of Claim 65, wherein the receiver is panitioned into one of a set of 
groups S|,,..,S^, wherein "w" is an integer, and the groups establish subtrees in a tree defining nodes and 
leaves. 

I0$3-13I.AM1 
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67. (original) The receiver of Claim 66, wherein subsets Si„ derived from the set of groups 

S, define a cover. 

68. (canceled). 

69. (original) The receiver of Claim 67, wherein the receiver must store log N keys, wherein N 
is the total number of receivers* 

70. (previously presented) A receiver of content^ conq)rising; 
means for storing respective private information I„; 

means for receiving at least one session encryption key K encrypted with plural subset keys, 
the session key encrypting content; and 

means for obtaining at least one subset key using the private information such that the session 
key K can be decrypted to play the content, wherein the receiver receives content in at least one 
message defining a header, and wherein die receiver processes the message using at most log log N 
operations plus a single decryption operation, wherein N is the total number of receivers. 

7L (original) The receiver of Claim 67, wherein a revoked set R defines a spannhig tree, and 
subtrees having roots attached to nodes of the spanning tree define the subsets. 
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72. (origiiial) The receiver of Claim 67, wherein the tree includes a toot and plural nodes, each 
node having at least one associated label, and wherein each subset includes all leaves in a subtree rooted at 
some node v^ that are not in the subtree rooted at some other node Vj that descerxls from V|. 

73 » (previously presented) A receiver of content, comprising: 
means for storing respective private information i„; 

means for receiving at least one session encryption key K encrypted with plural subset keys, 
the session key encrypting content; and 

means for obtaining at least one subset key using the private information such diat the session 
key K can be decrypted to play the content, wherein the receiver receives content in a message having 
a header including at most 2r-l subset keys and encryptions, wherein r is the number of receivers in 
the revoked set R. 

74. (previously presented) A receiver of content, comprising; 
means for storing respective private information I„; 

means for receiving at least one session encryption Icey K encrypted with plural subset keys, 
the session key encrypting content; and 

means for obtaining at least one subset key using the private information such that the session 
key K can be decrypted to play the content, wherein the receiver must store ,51og^ N ,5log N + 1 
keys, wherein N is the total number of receivers. 
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75. (previously presented) A receiver of content^ coniprising: 
means for storing respective private information I„; 

means for receiving at least one session encryption key K encrypted with plural subset keys* 
the session key encrypting content; and 

n^ans for obtaining at least one subset key using the private information such that the session 
key K can be decrypted to play the content, wherein content is provided to the receiver in at least one 
message, and wherein the receiver processes the message using at most log N operations plus a single 
decryption operation, wherein N is the total number of receivers. 

76. (original) The receiver of Claim 72, wherein the receiver decrypts the subset key by 
evaluating a pseudorandom sequence generator. 

77. (previously presented) A receiver of content, comprising: 
a data storage storing respective private information I„; 

a processing device receiving at least one session encryption key K encrypted with plural 
subset keys, the session key encrypting content, the processing device obtaining at least one subset 
key usiiig the private information such that the session key K can be decrypted to play the content, 
wherein the receiver receives content in at least one message defining a header, and wherein the 
receiver processes the tnessage using at most log log N op^*ations plus a single decryption operation, 
wherein N is the total number of receivers. 
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78. (original) The receiver of Claim 77, wherein the receiver is partitioned into one of a set of 
groups S,,...,S^ wherein "w" i$ an integer, and the groups establish subtrees in a tree. 

79. (original) The receiver of Claim 78, wherein subsets S^,,.. .,Si„ derived from the set of groups 
S],...,Sv define a cover. 

80. (original) The receiver of Claim 79, wherein the receiver receives content in at least one 
nffissage defining a header, and the header includes at most r*log(N/r) subset keys and encryptions, wherein 
r is the number of receivers in a revoked ^t R and N is the total number of receivers. 

81 . (original) The receiver of Claim 79, wherein the receiver must store log N keys, wherein N 
is the total number of receivers. 

82. (canceled), 

83. (original) The receiver of Claim 79, wherein one revoked set R defines a spanning tree, and 
subtrees having roots attached to iKxIes of the spanning tree define the subsets. 

84. (original) The receiver of Claim 79, wherein the tree includes a root and plural nodes, each 
node having at least one associated label, and wherein each subset includes all leaves in a subtree rooted at 
some node V| that are not in the subtree rooted at some other node Vj diat descends from V|. 
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85. (original) The receiver of Claim 84, wherein the receiver receives content in a message having 
a header including at most 2r-1 subset keys and encryptions, wherein r is the number of receivers in the 
revoked set R. 

86. (original) The receiver of Claim 84, wherein the receiver must store .51og^ N + .Slog N -4- 1 
keys, wherein N is the total number of receivers. 

87. (original) The receiver of Claim 84, wherein content is provided to the receiver in at least 
one message, and wherein the receiver processes the message using at most log N operations plus a single 
decryption operation, wherein N is the total number of receivers. 

88. (original) The receiver of Claim 84, wherein the receiver decrypts the subset key by 
evaluating a pseudorandom sequence generator. 

89-94 (canceled). 

95. (original) The computer of Claim 42, wherein the act of partitioning is undertaken by a 
system computer in a system of receivers separate from the system computer. 

96« (original) The computer of Claim 42, wherein the act of partitioning is undertaken by a 
receiver computer. 
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97. (original) The receiver of Claim 67, wherein the receiver derives the subsets in the cover. 

98. (new) The computer of Claim 41 , wherein the method acts include using private informarion 
to decrypt the session key. 
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